CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
96501 | CVE-2016-9681 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in Serendipity before 2.0.5 allow remote authenticated users to inject arbitrary web script or HTML via a category or directory name. | Assigned (20161130) | None (candidate not yet proposed) | View | |
96502 | CVE-2016-9682 | Candidate | The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to two Remote Command Injection vulnerabilities in its web administrative interface. These vulnerabilities occur in the diagnostics CGI (/cgi-bin/diagnostics) component responsible for emailing out information about the state of the system. The application doesn"t properly escape the information passed in the "tsrDeleteRestartedFile" or "currentTSREmailTo" variables before making a call to system(), allowing for remote command injection. Exploitation of this vulnerability yields shell access to the remote machine under the nobody user account. | Assigned (20161130) | None (candidate not yet proposed) | View | |
96503 | CVE-2016-9683 | Candidate | The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. This vulnerability occurs in the "extensionsettings" CGI (/cgi-bin/extensionsettings) component responsible for handling some of the server"s internal configurations. The CGI application doesn"t properly escape the information it"s passed when processing a particular multi-part form request involving scripts. The filename of the "scriptname" variable is read in unsanitized before a call to system() is performed - allowing for remote command injection. Exploitation of this vulnerability yields shell access to the remote machine under the nobody user account. This is SonicWall Issue ID 181195. | Assigned (20161130) | None (candidate not yet proposed) | View | |
96504 | CVE-2016-9684 | Candidate | The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. This vulnerability occurs in the "viewcert" CGI (/cgi-bin/viewcert) component responsible for processing SSL certificate information. The CGI application doesn"t properly escape the information it"s passed in the "CERT" variable before a call to system() is performed - allowing for remote command injection. Exploitation of this vulnerability yields shell access to the remote machine under the nobody user account. | Assigned (20161130) | None (candidate not yet proposed) | View | |
96505 | CVE-2016-9685 | Candidate | Multiple memory leaks in error paths in fs/xfs/xfs_attr_list.c in the Linux kernel before 4.5.1 allow local users to cause a denial of service (memory consumption) via crafted XFS filesystem operations. | Assigned (20161130) | None (candidate not yet proposed) | View |
Page 19301 of 20943, showing 5 records out of 104715 total, starting on record 96501, ending on 96505